Skip to content
arrow_back
search
ISM-1951 policy ASD Information Security Manual (ISM)

Disable Hard Match Takeover in Microsoft Entra Connect

Ensure that the hard match feature is turned off to prevent unauthorised access in Microsoft Entra Connect servers.

record_voice_over

Plain language

This control is about making sure a specific feature called hard match takeover in Microsoft Entra Connect is turned off. This is important because having it on could let someone gain control of user accounts without permission, putting your business data at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Hard match takeover is disabled for Microsoft Entra Connect servers.
policy ASD Information Security Manual (ISM) ISM-1951
priority_high

Why it matters

If hard match takeover is enabled in Entra Connect, attackers can take over synced identities by matching on-premises accounts to cloud users.

settings

Operational notes

Periodically confirm the Entra Connect setting for hard match takeover remains disabled after upgrades, config changes or server rebuilds.

Mapping detail

Mapping

Direction

Controls